Device Group Authorization via Peer-to-Peer Code Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users with multiple devices face inefficiencies in sharing data between them, as existing methods require multiple user inputs and lack secure synchronization, especially when involving centralized authorities that can decrypt synchronized data.

Innovation Solution

A method allowing a device to join a synchronization group and authorize with a centralized entity using a single process with minimal user inputs, employing encrypted data synchronization and a secure channel to prevent centralized entity access, utilizing a code generated on one device and input on another to prove possession and create a trusted channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If devices synchronize data through a centralized authority, then unified access and data sharing are enabled, but the centralized authority can decrypt user data compromising security

Engineering Contradiction:
Improveunified access to centralized authorityVSAvoidcentralized authority can decrypt user data
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces device-to-device communication as an intermediary channel that bypasses the centralized authority for data synchronization. Devices establish direct peer-to-peer connections to share data, eliminating the need for the centralized authority to decrypt user data while maintaining unified access through the same authority for authentication and account management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple user inputs are required for authorization and synchronization, then security is improved, but user convenience and operation speed deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser input requirements
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple authorization processes into a single integrated flow. The device simultaneously performs authentication with the centralized authority and establishes synchronization credentials through one unified process, eliminating the need for separate user inputs for each operation and improving both security and user convenience.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary authentication and establishes trust relationships before requiring user input for data synchronization. By pre-establishing security channels and validating device identities in advance, the system reduces the number of required user inputs while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a code is generated on one device and input on another, then proof of possession and secure channel are established, but the process complexity increases

Engineering Contradiction:
Improveproof of possessionVSAvoidauthorization process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically generates, transmits, and validates the authorization code without requiring manual intervention or complex user actions. The code generation and verification processes are handled autonomously by the system, simplifying the user experience while maintaining secure proof of device possession.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11444766B2Combined authorization process
Publication Date: 2022.09.13 APPLE INC
  • US11444766B2 patent drawing
  • US11444766B2 patent drawing
  • US11444766B2 patent drawing

AI summary

Some embodiments provide a method for a first device to join a group of related devices. The method receives input of a password for an account with a centralized entity and a code generated by a second device in the group. When the second device determines that the code input on the first device matches the generated code, the method receives an authentication code from the second device for authorizing the first device with the entity as a valid device for the account. The method uses the password and information regarding the first device to generate an application to the group. After sending the application to the second device, the method receives information from the second device that enables the first device to add itself to the group. The second device verifies the generated application, and the method uses the information received from the second device to join the group.